CVE-2017-0356: Authentication bypass via repeated parameters
Published Apr 13, 2018
·Updated
A flaw, similar to to CVE-2016-9646, exists in ikiwiki before 3.20170111, in the passwordauth plugin's use of CGI::FormBuilder, allowing an attacker to bypass authentication via repeated parameters.
Affected Software
4 affected componentsFixes available
debian/ikiwiki
3.20190228-13.20200202.3-1
Ikiwiki ikiwiki<3.20170111
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Event History
Apr 13, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-0356?
CVE-2017-0356 is classified as a vulnerability that allows for authentication bypass, posing a significant security risk.
2
How do I fix CVE-2017-0356?
To fix CVE-2017-0356, upgrade to version 3.20190228-1 or 3.20200202.3-1 of the ikiwiki package.
3
Which software is affected by CVE-2017-0356?
CVE-2017-0356 affects ikiwiki versions prior to 3.20170111.
4
Who can exploit CVE-2017-0356?
Any attacker with the ability to send requests to the ikiwiki application can exploit CVE-2017-0356 through crafted parameters.
5
What are the consequences of exploiting CVE-2017-0356?
Exploiting CVE-2017-0356 allows attackers to bypass authentication, potentially leading to unauthorized access and data compromise.